28 researchers. 9 days. 45 valid critical or high severity issues uncovered.
@amazon's first-ever In-Person Challenge brought together top security researchers to test its systems.
A HackerOne Challenge is more than just a bug bounty—it’s an invite-only, time-bound offensive testing program focused on finding high-impact vulnerabilities fast.
Here’s what this one produced:
👀 222 vulnerability submissions triaged by a dedicated HackerOne pod
💪 129 valid issues: ~60% of all submissions!
💥 12 critical & 33 high-severity findings
🧠 The opportunity for in-house teams to observe researchers’ reconnaissance & attack methodologies firsthand—gaining a deeper understanding of potential security issues
This is what modern, proactive security looks like.